CERT-In Empanelled — Since 2008 — mandatory for SEBI compliance audits

SEBI CSCRF Compliance: End-to-End Audit and CertificationServices

The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) 2024 mandates comprehensive security controls for all regulated entities. Security Brigade delivers VAPT, Attack Surface Management, and CART from a single CERT-In empanelled vendor trusted by SEBI itself.

6,700+Assessments
700+Clients
150+Team
2006Founded

Trusted by India's leading enterprises

ICICI Bank
HDFC
PhonePe
Swiggy
Asian Paints
Mahindra
L&T
Aditya Birla
Pernod Ricard
Yes Bank
DHL Express
Etihad Airways
Amazon Pay
Sephora
Groww
Pharmeasy
BillDesk
Jubilant Foods
ICICI Bank
HDFC
PhonePe
Swiggy
Asian Paints
Mahindra
L&T
Aditya Birla
Pernod Ricard
Yes Bank
DHL Express
Etihad Airways
Amazon Pay
Sephora
Groww
Pharmeasy
BillDesk
Jubilant Foods
STEP 01

Assess

We perform a comprehensive gap analysis mapping your current security posture against all SEBI CSCRF control requirements. This includes VAPT, attack surface discovery via ShadowMap, policy and process review, and infrastructure configuration audits.

STEP 02

Remediate

Our team delivers a prioritized remediation roadmap with specific, actionable fixes for every identified gap. We conduct walkthrough sessions with your IT and development teams to ensure vulnerabilities and process gaps are resolved efficiently.

STEP 03

Certify

After remediation validation and retesting, we deliver the complete SEBI CSCRF compliance audit report, gap closure documentation, and security assessment certificate — ready for submission to SEBI or your exchange-level compliance team.

What is SEBI CSCRF?

The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) is a 2024 regulatory mandate issued by the Securities and Exchange Board of India requiring all SEBI-regulated entities to implement comprehensive cybersecurity controls, conduct regular security audits by CERT-In empanelled auditors, and establish cyber resilience capabilities including continuous attack surface monitoring and incident response readiness.

Who Needs to Comply with SEBICSCRF?

The framework applies to all SEBI-regulated entities across the capital markets ecosystem

Stock Exchanges and Clearing Corporations

NSE, BSE, MCX, NCDEX, and all recognized exchanges and clearing corporations fall under the highest tier with the most stringent requirements.

Depositories and Registrars

NSDL, CDSL, and registrar and transfer agents must comply with enhanced data protection and system audit requirements.

Stock Brokers and Trading Members

All stock brokers, trading members, and clearing members must implement CSCRF controls proportionate to their operational scale.

Mutual Funds and AMCs

Asset management companies, mutual fund houses, and their registrars must secure investor data, trading platforms, and NAV calculation systems.

Merchant Bankers and Investment Advisers

SEBI-registered merchant bankers, portfolio managers, investment advisers, and research analysts must implement appropriate cybersecurity controls.

KYC Registration Agencies and Credit Rating Agencies

KRAs, credit rating agencies, and other market infrastructure institutions handling sensitive investor and issuer data must comply.

Methodology

7 steps. Zero guesswork.

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Scoping and Entity Classification

We classify your entity under the appropriate CSCRF tier, identify applicable control requirements, map your technology landscape, and define the complete audit scope including all applications, networks, and infrastructure components.

02

Attack Surface Discovery

ShadowMap, our proprietary External Attack Surface Management platform, performs comprehensive discovery of all internet-facing assets, shadow IT, exposed services, leaked credentials, and digital footprint risks specific to your organization.

03

Vulnerability Assessment and Penetration Testing

Deep VAPT across all in-scope applications, APIs, networks, and infrastructure. Our CERT-In empanelled team performs manual penetration testing augmented by AI-validated coverage analysis, following structured workflows managed through Lemon.

Testing
04

Policy, Process, and Governance Review

Comprehensive review of your cybersecurity policies, incident response procedures, access control frameworks, data protection practices, and governance structures against CSCRF control requirements.

05

Gap Analysis and Remediation Roadmap

Detailed gap analysis report mapping current state against every applicable CSCRF control. Each gap includes severity classification, business impact, specific remediation steps, and implementation priority. Walkthrough sessions conducted with your IT and compliance teams.

Delivery
06

Remediation Support and Retesting

We support your teams through the remediation process with clarification calls, developer walkthroughs, and multiple rounds of retesting to validate that vulnerabilities and control gaps have been effectively resolved.

07

Final Report and Compliance Certification

Delivery of the complete SEBI CSCRF compliance audit report, executive summary for board presentation, gap closure documentation, and security assessment certificate. All documentation formatted for regulatory submission.

"Security Brigade's structured approach through Lemon gave us complete visibility into the testing process. The three-layer review caught issues that our previous vendor missed entirely. Their reports were the first our developers could actually act on without a follow-up call."
CISO, Leading Indian BFSI Enterprise
Top 5 Private Sector Bank · Engaged since 2019

Read more client stories →

The Platform

Powered by Lemon

Most firms rely on individual tester skill. We built a platform that makes quality structural — informed by 6,700+ previous assessments.

lemon.securitybrigade.com/project/PRJ-2847
D
C
F
R
T
PROJECT PRJ-2847
Coverage Validation — acmecorp.com
94% covered
Endpoints
247 / 263
Parameters
1,847
Auth Flows
12 / 12
JS Routes
38 / 41
AI flagged 3 undiscovered endpoints
/api/v2/admin/export, /api/v2/billing/webhook, /internal/healthcheck
L1 Complete
L2 In Review
L3 Pending

Lemon: Audit Management Platform

Manages the entire CSCRF audit lifecycle from scoping to certification. Every finding, artifact, and remediation action is tracked centrally with complete traceability for regulatory documentation.

ShadowMap: Continuous Attack Surface Monitoring

Fulfills the CSCRF continuous monitoring requirement with real-time external attack surface discovery, dark web monitoring, credential leak detection, and automated alerting.

Real-Time Client Dashboard

Your compliance and IT teams see findings as they are identified, track remediation progress in real time, and download reports directly — eliminating email clutter and status meeting overhead.

Compliance-Ready

Audit-ready reporting for every framework

As a CERT-In empanelled firm, our reports are accepted by all major Indian and global regulators.

VAPT (Web, Mobile, API, Network)
Covers the CSCRF mandate for regular vul
External Attack Surface Management (ShadowMap)
Satisfies the continuous monitoring and
Cyber Audit and Resilience Testing (CART)
Comprehensive audit of cybersecurity con
Policy and Process Review
Assessment of cybersecurity governance,
Cloud and Infrastructure Security Review
Covers CSCRF requirements for cloud conf
Third-Party Risk Assessment
Vendor and third-party security assessme

Industries

700+ clients across verticals

Every type of application architecture and business logic pattern — tested.

BFSIICICI Bank, HDFC, Yes Bank, UTI MF, Edelweiss
Fintech & PaymentsPhonePe, Amazon Pay, Groww, BillDesk
ManufacturingMahindra, Asian Paints, L&T, Hindalco
Retail & ConsumerSwiggy, Sephora, Pernod Ricard, Jubilant
Aviation & LogisticsEtihad Airways, DHL Express, Shadowfax
HealthcareCloudNine, Pharmeasy, Wave Health

Deliverables

What you get

Reports for two audiences — executives who need the risk picture, and developers who need to fix the issues. With code-level guidance, not vague advice.

SEBI CSCRF Compliance Audit Report

Complete audit report mapping your security posture against every applicable CSCRF control, formatted for regulatory submission to SEBI or exchange compliance teams.

Gap Analysis Report

Detailed assessment of control gaps with severity classification, business impact analysis, and specific remediation guidance for each identified gap.

Technical VAPT Report

Full vulnerability descriptions with step-by-step proof-of-concept evidence, request/response examples, CVSS severity scoring, and technology-specific remediation code.

Executive Summary and Board Deck

Non-technical overview of compliance status, risk posture, and remediation progress designed for board presentations and audit committee briefings.

Prioritized Remediation Roadmap

Actionable remediation plan organized by severity and implementation effort, enabling your team to address critical gaps first within regulatory timelines.

Attack Surface Monitoring Report

ShadowMap-generated report covering external asset inventory, exposed services, leaked credentials, dark web exposure, and continuous monitoring findings.

Security Assessment Certificate

Formal certificate confirming completion of the SEBI CSCRF compliance audit by a CERT-In empanelled auditor, suitable for regulatory documentation and compliance records.

Remediation Validation Report

Post-remediation retesting report confirming that identified vulnerabilities and control gaps have been resolved, providing closure documentation for audit trails.

FAQ

Common questions

Can't find what you're looking for? Talk to our team.

Contact us
What is the SEBI CSCRF compliance deadline?+
SEBI issued the Cybersecurity and Cyber Resilience Framework in 2024 with phased implementation timelines based on entity classification. Market Infrastructure Institutions have the earliest deadlines, followed by qualified regulated entities and other SEBI-registered intermediaries. Contact us to determine your specific compliance timeline based on your entity classification and tier.
Is a CERT-In empanelled auditor mandatory for SEBI CSCRF audits?+
Yes, SEBI CSCRF explicitly requires that cybersecurity audits be conducted by CERT-In empanelled organizations. Security Brigade has been CERT-In empanelled since 2008, making us one of the longest-standing empanelled auditors in India. This empanelment is a mandatory prerequisite — engaging a non-empanelled vendor means the audit will not be accepted by SEBI.
What is the difference between SEBI CSCRF and the earlier SEBI cybersecurity circular?+
SEBI CSCRF 2024 is a comprehensive replacement and significant expansion of previous SEBI cybersecurity circulars. It introduces mandatory attack surface management, cyber resilience testing, enhanced governance requirements, and tiered compliance obligations based on entity classification. The earlier circulars focused primarily on basic cybersecurity controls, while CSCRF mandates a much broader and deeper security posture.
Can one vendor handle all SEBI CSCRF requirements?+
Yes. Security Brigade is one of the few CERT-In empanelled vendors that can deliver VAPT, attack surface management, and cyber audit and resilience testing from a single engagement. Most organizations otherwise need to engage three or more separate vendors, creating coordination overhead, inconsistent methodology, and fragmented documentation. Our integrated approach through Lemon and ShadowMap ensures consistent coverage and unified reporting.
How long does a SEBI CSCRF compliance audit take?+
A typical SEBI CSCRF compliance engagement takes six to eight weeks from scoping to final certification, depending on the number of in-scope applications, network segments, and the maturity of existing security controls. This includes gap analysis, VAPT, policy review, remediation support, retesting, and final report delivery. Organizations starting from a lower maturity baseline should allow additional time for remediation.
What does SEBI CSCRF compliance cost?+
The cost depends on your entity tier, number of in-scope applications and network components, the breadth of CSCRF controls applicable to your classification, and whether you require continuous monitoring via ShadowMap. Security Brigade provides detailed proposals after a free scoping consultation that assesses your specific compliance requirements and current security maturity.
Does SEBI CSCRF require continuous attack surface monitoring?+
Yes. SEBI CSCRF mandates continuous monitoring of external-facing digital assets, not just periodic point-in-time assessments. Our ShadowMap platform fulfills this requirement with real-time external attack surface discovery, dark web monitoring, credential leak detection, and automated alerting. ShadowMap can be deployed as a SaaS subscription for ongoing compliance.
How is SEBI CSCRF different from RBI cybersecurity requirements?+
While both frameworks mandate cybersecurity controls for financial entities, SEBI CSCRF is specifically designed for capital markets participants and includes requirements unique to trading systems, market surveillance, and investor data protection. RBI frameworks focus on banking, payment, and lending operations. Organizations regulated by both SEBI and RBI may need to comply with both frameworks. Security Brigade has deep experience with both and can optimize audit scope to minimize duplication.
What happens if my organization fails the SEBI CSCRF audit?+
Security Brigade's approach is designed to prevent this outcome. Our phased methodology starts with a gap analysis, giving you a clear picture of compliance gaps before the formal audit. We then support remediation and conduct retesting to validate that gaps are closed. The final audit report reflects your post-remediation posture. If issues remain, we provide a clear roadmap for resolution with prioritized timelines.
Does Security Brigade have experience auditing SEBI itself?+
Yes. Security Brigade has conducted security assessments for the Securities and Exchange Board of India, encompassing 1,089 scopes. This direct experience with the regulator gives us unparalleled insight into SEBI's expectations, standards, and the level of rigor they apply when evaluating compliance reports from regulated entities.

Start Your SEBI CSCRF Compliance Journey Today

Get a free scoping consultation with our capital markets compliance team

Typically responds within 1 business day · No commitment required

Get a Quote